NIST 800-171 Controls · Incident Response
IR.2.092 — Establish operational incident-handling capability
Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
What IR.2.092 means in plain English
You need a written plan for what to do when something goes wrong — a ransomware attack, a stolen laptop, an employee accidentally emailing CUI to the wrong person. The plan must cover six phases: (1) preparation (have the plan before you need it), (2) detection (how do you find out an incident happened), (3) analysis (figure out what happened and how bad it is), (4) containment (stop the bleeding — disconnect infected machines, revoke compromised accounts), (5) recovery (restore from backups, rebuild systems), and (6) user response (notify affected parties). For your 8-person shop, this does not need to be 200 pages — a clear 5-10 page Incident Response Plan that your whole team can understand and follow is perfect.
The assessment question
“Does the organization have a documented, approved, and accessible Incident Response Plan covering all six phases (prepare, detect, analyze, contain, recover, respond) — and does every employee know where to find it and what their role is?”
How to implement IR.2.092
- Draft an Incident Response Plan (IRP) using the NIST 800-61 Rev 2 framework as a template. At minimum, define: incident categories (malware, data breach, lost device, insider threat), severity levels, and response procedures for each.
- Assign roles even in your small team: one person is the Incident Response Lead (probably the owner or most technical person), one is the Communications Lead (who notifies customers, DOD, insurance), and define the backup if someone is unavailable.
- Create a one-page Emergency Contact Card listing: your IT support contact (MSP), your Cyber Insurance carrier's 24/7 claims line, DOD/DCSA reporting contact, your attorney, and your backup contact person.
- Define your containment playbooks: (a) Ransomware — immediately disconnect infected machine from network, call IT support, do NOT pay ransom; (b) Lost laptop — immediately remotely wipe via Microsoft 365 Mobile Device Management; (c) Phishing success — revoke session tokens, reset password, enable MFA.
- Store the IRP in at least two places: a printed copy in a physical binder and a digital copy in SharePoint or a USB drive kept off the main network — so it is accessible even if your systems are down.
Evidence your assessor will ask for
- Approved and dated Incident Response Plan document
- Evidence of plan distribution to all employees (email confirmation, signed acknowledgment)
- Emergency contact card with current phone numbers and reporting contacts
- Documented incident response roles and responsibilities with named individuals
- At least one completed incident log from a real or tabletop exercise event
Does AI prompt monitoring help with this control? It supports it.
AI prompt monitoring does not satisfy IR.2.092 on its own, but its output feeds the capability this control requires: the tamper-evident event stream of allowed and blocked AI prompts becomes detection signal, incident record, and reviewable audit material. Treat the AI firewall as one input to this practice, alongside the remediation steps above.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Incident Response controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.